Live data from Hacker News

Dutch university hit by cyber attack on its Windows systems

maastrichtuniversity.nl

21–30 of 37 posts

Re: Dutch university hit by cyber attack on its Windows systems

#21
post #12

Earlier quoted context omitted.

>Nah, in reality someone probably clicked a link in a malicious email that launched a backdoor on their computer. The likelihood of that approaches 100% on untrained users. In 2019 this is actually very unlikely. Driveby exploits have been pretty rare for years now.

It's still one of the top methods. See for example Symantec's report [1] with lots of data. [1] https://www.symantec.com/content/dam/symantec/docs/reports/i...

I literally just got a call about someone being hit. The avenues used to penetrate are email spam and RDP.

Re: Dutch university hit by cyber attack on its Windows systems

#22

Are there any documented reports of Linux/Unix systems ever being hit by ransomware? Or files on NAS appliances (NetApp, Isilon, etc) being encrypted in a way that is unrecoverable (especially since snapshots can be scheduled regularly)? Certainly you can steal data from non-Windows systems, so exfiltration attacks are similar on both, but AFAICT, these "we've got your data" style attacks are unique to Windows. If an…

I had a linux system hit with a virus early 2000s. I had more confidence than linux skills back then and made some colossal blunders to make it happen. But whatever you use as your daily machine, it isn't immune. It's a smaller target, but there is still malware out there for Linux. One of the first widespread computer worms was Unix based[1].

[1] https://en.wikipedia.org/wiki/Morris_worm

PS Edit: Many routers are linux/unix based so it is a much bigger target than a lot of people on this thread are making out. If you have control of a company's routers you are in position to do a lot of damage.

Re: Dutch university hit by cyber attack on its Windows systems

#24
post #17

Earlier quoted context omitted.

All of this shit comes through phishing emails with Office docs containing malicious macros or links. Literally 99% of it. All of these stories should say "Sysadmins ignored best practices of disabling unapproved macros, allowing malware to gain a foothold, dump privileged credentials on the system, and move laterally through the environment with ease"

Its a university, so more likely "Sysadmins implemented best practices of disabling unapproved macros, but due to an extreme number of complaints from academic staff that all their research would be ruined, had to disable it again."

So you allow it for those folks and block it for the rest, there will always be edge cases but you need to reduce risk and attack surface. So hopefully they have those academic staff members on record as accepting the risk.

Re: Dutch university hit by cyber attack on its Windows systems

#25

Earlier quoted context omitted.

Linux systems are less targeted because they're less commonly used, their userbase on average knows more about technology and they're inherently more secure.

Ha! This got a good chuckle out of me. Check again; this happens more often than you would think in the web hosting business, especially the small to medium business segment. "It's just a website how hard could it be?" If I had a nickel for every RHEL 5 (yes, 5!) box still running after we begged customers to please, please move to something actually receiving patches... In theory ransomware shouldn't have as large o…

I meant for people using it as their daily driver operating system (not servers).

Most linux enthusiasts know a bit more/are interested in technology so they would be likely to engage in better security practices than a typical "home user" using Windows. In addition features like package managers and actually functioning permissions systems help as well (how long has Windows had public UAC bypasses?)

Of course you're correct and most servers run linux and get hacked every millisecond otherwise though because they don't keep them updated.

Re: Dutch university hit by cyber attack on its Windows systems

#26
Big list of ransomware or possible ransomware attacks in 2019 at:

https://techtalk.pcmatic.com/2019/01/09/ransomware-attacks-2...

I think the date should be December 2019 (not January), judging from the list of incidents by month.

One I know of, against Regis University in Colorado, occurred in late August (first reports from August 22).

https://www.regisupdates.com/regis-quick-updates/test-post

It's mainly a Windows shop. Lots of disruptions for weeks (I teach there part-time, but was not teaching that term). By November(!) things were pretty much back to normal:

https://www.regisupdates.com/regis-quick-updates/its-updates...

Re: Dutch university hit by cyber attack on its Windows systems

#27
post #14

Are there any documented reports of Linux/Unix systems ever being hit by ransomware? Or files on NAS appliances (NetApp, Isilon, etc) being encrypted in a way that is unrecoverable (especially since snapshots can be scheduled regularly)? Certainly you can steal data from non-Windows systems, so exfiltration attacks are similar on both, but AFAICT, these "we've got your data" style attacks are unique to Windows. If an…

Basically 99.99% of companies and governments use windows so its unlikely to see this happening.

What orifice did you pull that stat from?

Re: Dutch university hit by cyber attack on its Windows systems

#28
post #17

Earlier quoted context omitted.

Its a university, so more likely "Sysadmins implemented best practices of disabling unapproved macros, but due to an extreme number of complaints from academic staff that all their research would be ruined, had to disable it again."

So you allow it for those folks and block it for the rest, there will always be edge cases but you need to reduce risk and attack surface. So hopefully they have those academic staff members on record as accepting the risk.

>So hopefully they have those academic staff members on record as accepting the risk.

Then what? Use them as the scapegoat when the network does get compromised? Feels like the exact opposite of blameless postmortems.

Re: Dutch university hit by cyber attack on its Windows systems

#29
post #6

Allegedly it's the CLOP ransomware. "All dhcp-servers, Exchange-servers, domaincontrollers and networkdrives have been encrypted." Source in Dutch: https://tweakers.net/nieuws/161538/deel-diensten-universitei... Clop: https://securingtomorrow.mcafee.com/blogs/other-blogs/mcafee...

Uh so they don’t have up-to-date AV definitions? Sounds like McAfee was on it in August and Windows Defender has it no later than the 9th of December [1].

[1] I’d expect it to be earlier than that, but this article date is the only thing I’ve found: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo...

Post reply on HN